I'm attempting to add Jira Cloud access into a web app I'm developing. I (now!) understand the CORS issues with doing this using the rest API. So I've got Oauth 2.0 authentication setup and can happily make access requests, but only for the 3600 seconds of the "expires_in" field. I (now!) understand the idea behind using a refresh token to generate a new access token but this is where I've become stuck.
I can use a refresh token using curl and generate a new access token but only if using curl, when I try from my web app I get the dreaded CORS error:
Cross-Origin Request Blocked: The Same Origin Policy disallows reading the remote resource at https://auth.atlassian.com/oauth/token. (Reason: CORS header ‘Access-Control-Allow-Origin’ missing)
So my question is how do I (can I even?) use a refresh token to generate a new access token and avoid a CORS error? I have to use the <a href="https://api.atlassian.com/ex/jira/%7Bcloudid%7D/%7Bapi" target="_blank" rel="noopener nofollow noreferrer">https://api.atlassian.com/ex/jira/{cloudid}/{api</a>} address when making api calls using oauth. Do I have to use an equivalent address to get a token?
Many thanks in advance.